CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13540 | CVE-2005-2334 | Candidate | Y.SAK allows remote attackers to execute arbitrary commands via shell metacharacters in the $no variable to (1) w_s3mbfm.cgi, (2) w_s3adix.cgi, or (3) w_s3sbfm.cgi. | Assigned (20050720) | None (candidate not yet proposed) | View | |
8722 | CVE-2004-0294 | Candidate | YaBB 1 SP 1.3.1 displays different error messages when a user exists or not, which makes it easier for remote attackers to identify valid users and conduct a brute force password guessing attack. | Proposed (20040318) | NOOP(4) Armstrong, Cole, Cox, Wall | View | |
2422 | CVE-2000-0853 | Entry | YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a .. (dot dot) attack. | View | |||
10090 | CVE-2004-1662 | Candidate | YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in a PHP error message. | Assigned (20050221) | None (candidate not yet proposed) | View | |
13502 | CVE-2005-2296 | Candidate | YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path. | Assigned (20050717) | None (candidate not yet proposed) | View |
Page 20895 of 20943, showing 5 records out of 104715 total, starting on record 104471, ending on 104475